Microsoft and Sophos reported separate but closely aligned social-engineering campaigns in which attackers impersonated IT support staff over Microsoft Teams, phone calls, and related pretexts to trick employees into granting remote access through Quick Assist or other support tools. Microsoft attributed its activity to Storm-1811, which used vishing and email-bombing to gain access, steal credentials through EvilProxy, and deploy tools including Qakbot, Cobalt Strike, ScreenConnect, NetSupport Manager, OpenSSH tunneling, and SystemBC before rolling out Black Basta ransomware with PsExec. Microsoft said it suspended malicious Teams accounts and tenants involved in the impersonation activity and added stronger Quick Assist warnings and trust indicators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft said it suspended malicious Teams accounts and tenants involved in the impersonation activity and was improving Quick Assist warnings and trust transparency in response to the campaign.
Sophos observed that at least three STAC4749 intrusions culminated in Chaos ransomware deployment, including one case that progressed from initial access to encryption in under 17 hours.
Sophos reported that a Microsoft Teams voice phishing campaign tracked as STAC4749 targeted dozens of organizations in Canada and the United States between February and June 2026 by impersonating IT support staff and persuading users to grant remote access.
By late May 2024, Storm-1811 had expanded its social engineering activity to Microsoft Teams messages and calls impersonating help desk or IT staff to trick users into granting remote access.
Microsoft Threat Intelligence reported that the financially motivated group Storm-1811 had been abusing Quick Assist since mid-April 2024 as part of intrusion chains that led to credential theft, malware delivery, and follow-on Black Basta ransomware activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcesophos.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.